WebOrbiton
v3.0.0.0

FlatlyPage

124 lines · 5.7 KB
  1. <?php
  2. ​
  3. require_once '../config.php';
  4. ​
  5. $isLocalhost = in_array($_SERVER['REMOTE_ADDR'] ?? '', ['127.0.0.1', '::1', 'localhost']);
  6. $isCLI = php_sapi_name() === 'cli';
  7. ​
  8. if (!$isLocalhost && !$isCLI) {
  9. http_response_code(403);
  10. die('Access denied. This tool is only available from localhost.');
  11. }
  12. ​
  13. $hash = '';
  14. $password = '';
  15. ​
  16. if ($_SERVER['REQUEST_METHOD'] === 'POST' && isset($_POST['password'])) {
  17. $password = $_POST['password'];
  18. $hash = password_hash($password, PASSWORD_DEFAULT);
  19. }
  20. ?>
  21. <!DOCTYPE html>
  22. <html lang="en">
  23. <head>
  24. <meta charset="UTF-8">
  25. <meta name="viewport" content="width=device-width, initial-scale=1.0">
  26. <title>Password Hash Generator - FlatlyPage CMS</title>
  27. <script src="https://cdn.tailwindcss.com"></script>
  28. <?= admin_font_head() ?>
  29. <style>
  30. * { font-family: var(--font-interface, 'Space Grotesk'), sans-serif; }
  31. </style>
  32. </head>
  33. <body class="min-h-screen bg-gray-100 py-12 px-4">
  34. <div class="max-w-lg mx-auto">
  35. <div class="bg-white rounded-2xl shadow-lg p-8">
  36. <div class="text-center mb-8">
  37. <div class="inline-flex items-center justify-center w-12 h-12 bg-blue-100 rounded-xl mb-4">
  38. <svg class="w-6 h-6 text-blue-600" fill="none" stroke="currentColor" viewBox="0 0 24 24">
  39. <path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M12 15v2m-6 4h12a2 2 0 002-2v-6a2 2 0 00-2-2H6a2 2 0 00-2 2v6a2 2 0 002 2zm10-10V7a4 4 0 00-8 0v4h8z"/>
  40. </svg>
  41. </div>
  42. <h1 class="text-xl font-bold text-gray-900">Password Hash Generator</h1>
  43. <p class="text-gray-500 text-sm mt-1">Generate a secure password hash</p>
  44. </div>
  45. ​
  46. <form method="POST" action="" class="space-y-5">
  47. <div>
  48. <label for="password" class="block text-sm font-medium text-gray-700 mb-2">
  49. Password to hash
  50. </label>
  51. <input type="text"
  52. id="password"
  53. name="password"
  54. required
  55. value="<?php echo e($password); ?>"
  56. class="w-full px-4 py-3 border border-gray-300 rounded-xl focus:ring-2 focus:ring-blue-500 focus:border-blue-500"
  57. placeholder="Enter password">
  58. </div>
  59. ​
  60. <button type="submit"
  61. class="w-full py-3 px-4 bg-blue-600 text-white font-semibold rounded-xl hover:bg-blue-700 transition-colors">
  62. Generate Hash
  63. </button>
  64. </form>
  65. ​
  66. <?php if ($hash): ?>
  67. <div class="mt-6 p-4 bg-gray-50 rounded-xl">
  68. <label class="block text-sm font-medium text-gray-700 mb-2">
  69. Generated hash:
  70. </label>
  71. <div class="relative">
  72. <textarea readonly
  73. id="hashOutput"
  74. class="w-full px-4 py-3 bg-white border border-gray-300 rounded-xl text-sm font-mono resize-none"
  75. rows="3"><?php echo e($hash); ?></textarea>
  76. <button type="button"
  77. onclick="copyHash()"
  78. class="absolute top-2 right-2 p-2 bg-gray-100 hover:bg-gray-200 rounded-lg transition-colors"
  79. title="Copy">
  80. <svg class="w-4 h-4 text-gray-600" fill="none" stroke="currentColor" viewBox="0 0 24 24">
  81. <path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M8 16H6a2 2 0 01-2-2V6a2 2 0 012-2h8a2 2 0 012 2v2m-6 12h8a2 2 0 002-2v-8a2 2 0 00-2-2h-8a2 2 0 00-2 2v8a2 2 0 002 2z"/>
  82. </svg>
  83. </button>
  84. </div>
  85. </div>
  86. ​
  87. <div class="mt-4 p-4 bg-amber-50 border border-amber-200 rounded-xl">
  88. <div class="flex items-start gap-3">
  89. <svg class="w-5 h-5 text-amber-600 flex-shrink-0 mt-0.5" fill="none" stroke="currentColor" viewBox="0 0 24 24">
  90. <path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M12 9v2m0 4h.01m-6.938 4h13.856c1.54 0 2.502-1.667 1.732-3L13.732 4c-.77-1.333-2.694-1.333-3.464 0L3.34 16c-.77 1.333.192 3 1.732 3z"/>
  91. </svg>
  92. <div class="text-sm text-amber-800">
  93. <p class="font-medium">Security Notice</p>
  94. <p class="mt-1">Do not use this tool in production. Passwords should only be hashed during registration or password changes.</p>
  95. </div>
  96. </div>
  97. </div>
  98. <?php endif; ?>
  99. </div>
  100. ​
  101. <div class="text-center mt-6">
  102. <a href="index.php" class="text-blue-600 hover:text-blue-700 text-sm font-medium">
  103. &larr; Back to login
  104. </a>
  105. </div>
  106. </div>
  107. ​
  108. <script>
  109. function copyHash() {
  110. const textarea = document.getElementById('hashOutput');
  111. textarea.select();
  112. document.execCommand('copy');
  113. const btn = event.currentTarget;
  114. const originalHTML = btn.innerHTML;
  115. btn.innerHTML = '<svg class="w-4 h-4 text-green-600" fill="none" stroke="currentColor" viewBox="0 0 24 24"><path stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M5 13l4 4L19 7"/></svg>';
  116. setTimeout(() => {
  117. btn.innerHTML = originalHTML;
  118. }, 2000);
  119. }
  120. </script>
  121. </body>
  122. </html>
  123. ​